
Twittee Text Tweet Security & Risk Analysis
wordpress.org/plugins/twittee-text-tweetTwittee enables visitors to tweet your keyword rich content on Twitter. Add Twittee shortcode to post and let your visitors do the rest. Easy!
Is Twittee Text Tweet Safe to Use in 2026?
Use With Caution
Score 64/100Twittee Text Tweet has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "twittee-text-tweet" plugin version 1.0.8 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and not engaging in file operations or external HTTP requests. It also has a very limited attack surface, with all entry points identified not requiring explicit authentication checks. However, significant concerns arise from the static analysis results. Notably, 100% of its output is not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities where user-supplied data could be rendered directly in the browser without sanitization.
The plugin has a history of known vulnerabilities, with one medium severity Cross-Site Scripting (XSS) issue that remains unpatched. This pattern of XSS vulnerabilities, combined with the current lack of proper output escaping, strongly suggests that new XSS vulnerabilities could easily be introduced or may already exist. The taint analysis, while showing a small number of flows, flags two flows with unsanitized paths, which, coupled with the lack of output escaping, further exacerbates the XSS risk. The absence of nonce checks and capability checks on the identified entry points, although the attack surface is small, could be exploited if any of the unsanitized output flows are triggered in a context where an attacker can influence the input.
In conclusion, while the plugin has some strengths in its handling of database queries and external interactions, the pervasive lack of output escaping and the history of unpatched XSS vulnerabilities make it a significant security risk. The presence of unsanitized taint flows further amplifies this concern. It is strongly recommended that users update to a version that addresses the known vulnerability and that developers implement robust output escaping for all dynamic content.
Key Concerns
- Unpatched CVE: Medium severity XSS
- 100% of output unescaped
- 2 unsanitized taint flows
- No nonce checks
- No capability checks
Twittee Text Tweet Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Twittee Text Tweet <= 1.0.8 - Reflected Cross-Site Scripting
Twittee Text Tweet Code Analysis
Output Escaping
Data Flow Analysis
Twittee Text Tweet Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Twittee Text Tweet Maintenance & Trust
Maintenance Signals
Community Trust
Twittee Text Tweet Alternatives
Official Twitter and Periscope plugin for WordPress. Embed content and grow your audience. Requires PHP 5.6 or greater.
Twitter Hash Tag Shortcode
twitter-hash-tag-shortcode
Displaying the most recent twitter status updates for a particular hash tag in your posts/pages using shortcode.
TechGasp Tweety Master
tweet-master
With TechGasp Tweety Master plugin you can display your latest tweets, favourite twitter lists and twitter buttons.
WP OptinJeet – Create Form Lists and Manage leads
wp-optinjeet
WP Optin Jeet List Manager is a powerful plugin that lets you generate email lists right from inside your blog.
Easy Twitter Feed Widget Plugin
easy-twitter-feed-widget
Add twitter feeds on your WordPress site by using the Easy Twitter Feed Widget plugin.
Twittee Text Tweet Developer Profile
3 plugins · 30K total installs
How We Detect Twittee Text Tweet
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/twittee-text-tweet/js/ttt_tweetAction.js/wp-content/plugins/twittee-text-tweet/js/tttwordballoon.js/wp-content/plugins/twittee-text-tweet/js/ttt_tweetAction.js/wp-content/plugins/twittee-text-tweet/js/tttwordballoon.jstwittee-text-tweet/js/ttt_tweetAction.js?ver=twittee-text-tweet/js/tttwordballoon.js?ver=HTML / DOM Fingerprints
data-tweetActiondata-tttwordballoonttt_wordballoon[twitteeid="tweetLinkjQuery("#tweetLinkjQuery.fn.tweetAction